PT-2004-3049 · Apple+1 · Cups+1

Published

2004-12-31

·

Updated

2024-08-01

·

CVE-2004-2154

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CUPS versions prior to 1.1.21rc1
Description The issue allows attackers to bypass intended Access Control Lists (ACLs) due to the case-sensitive treatment of a Location directive in cupsd.conf. This can be exploited via a printer name containing uppercase or lowercase letters that differ from what is specified in the directive.
Recommendations For versions prior to 1.1.21rc1, update to version 1.1.21rc1 or later to resolve the issue. As a temporary workaround, consider ensuring that all printer names and Location directives in cupsd.conf are specified with consistent case to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-2154
RHSA-2005:571
RHSA-2005_571

Affected Products

Cups
Red Hat